SonicWall confirms all of its cloud backup customers were affected by data breach

  • SonicWall cloud backup breach exposed firewall config files of many global customers
  • Attackers brute-forced MySonicWall, risking credential leaks and targeted network intrusions
  • SonicWall urges users to delete backups, rotate secrets, and recreate configurations locally

All companies using SonicWall’s MySonicWall cloud backup feature have had their firewall configuration files exposed in a recent cyberattack, the company has admitted.

After initially claiming “fewer than 5%” of its customer base was affected, the company has revealed the true scale of the incident.

In mid-September 2025, SonicWall warned its firewall customers to reset their passwords after unnamed threat actors brute-forced their way into the company’s MySonicWall cloud service. This tool allows SonicWall firewall users (typically businesses and IT teams) to back up their firewall configuration files, including network rules and access policies, VPN configurations, service credentials (LDAP, RADIUS, SNMP), or admin usernames and passwords (if stored in config).

Other services intact

In theory, the attackers could brute-force or decrypt the secrets, extracting credentials used in services tied to the firewall, understand network topology and rules – bypassing defenses more easily, and launch targeted attacks using insider knowledge on how the firewalls are configured.

“While encryption remains in place, possession of these files could increase the risk of targeted attacks,” the notification reads. “We are working to notify all impacted partners and customers and have released tools to assist with device assessment and remediation.”

At the time, SonicWall said that fewer than 5% of its customer base was affected by this incident which, at worst, would put the number of victims at 25,000.

However, it now seems that the actual number of victims is a lot greater – SonicWall claims it services roughly 500,000 customers globally, although that doesn’t mean that all of them are using firewall, or cloud backup services.

The company also said the attack did not affect other MySonicWall services, or customer devices, but still urged its customers to be vigilant, delete existing cloud backups, change their credentials, rotate shared secrets, and recreate new backups locally.

Via The Register

Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds. Make sure to click the Follow button!

And of course you can also follow TechRadar on TikTok for news, reviews, unboxings in video form, and get regular updates from us on WhatsApp too.

You might also like

Read more @ TechRadar

Latest posts

The best record players for 2025

Everyone knows by now that vinyl is back. The classic format has seen a resurgence for years at this point, and new albums these...

Caroline Flack’s truth finally comes out in new Disney+ documentary – and it’s the most harrowing watch of the year

Warning: this documentary has themes of suicide and domestic violence.In 2020, British TV presenter Caroline Flack took her own life two months after being...

Elden Ring Nightreign’s DLC could arrive sooner than you think

FromSoftware's parent company says Elden Ring Nightreign DLC is in the worksIt's due to release before the end of the financial year (March 2026)There...

Meta says it wants to invest $600 billion in US infrastructure and jobs by 2028

Meta is planning more AI data centers as part of its $600 billion spendIt wants to reduce emissions and replace the water it usesShares...

The Samsung Galaxy S26 series could be announced as soon as January, with new cameras and a battery boost

The Samsung Galaxy S26 series might be announced in late January and ship in mid-FebruaryWe're also hearing that only the Galaxy S26 Ultra might...

Optimizing for online sales: Your insider guide to Black Friday success

If, like me, you've ever run an online store, you probably have a love/hate relationship with the holiday sale season.On one hand, the stress...

The latest Garmin leak suggests it’s stealing Apple Watch’s most iconic hardware feature

A new leak points to a design change for Garmin watchesSome future models may come with a digital crown attachedThe new crown mechanism would...

This HP Victus 15 just broke the record for the cheapest RTX 4050 gaming laptop we’ve seen yet

Black Friday deals start earlier and earlier every year, especially at places that sell the biggest and best tech in the US. As one...

Looks like the new Mass Effect will indeed feature romancing options, as EA gives an update on the next series entry for N7 Day

EA has shared an update on the new Mass Effect gameThe post comes as part of the N7 Day (Mass Effect Day) celebrationsIt mentions...

Need a VPN for Wisconsin? These deals are available right now – just in time for Black Friday

The rollout of age verification laws is one of 2025’s biggest digital privacy stories — particularly in the United States and the United Kingdom.The...